Apple says it has patch for remote hack attack
August 9, 2010 By Byron Acohido, USA Today
Apple is quietly wrestling with a security conundrum. How the company handles it could dictate the pace at which cybercriminals accelerate attacks on iPhones and iPads.
Apple is hustling to issue a patch for a milestone security flaw that makes it possible to remotely hack - or jailbreak - iOS, the operating system for iPhones, iPads and iPod Touch.
The patch is completed, Apple spokeswoman Natalie Kerris said in an interview. But Kerris said on Friday that she was not able to give a time frame for its public release.
Jailbreaking refers to hacking iOS to download Web apps not approved by Apple. This used to be difficult. This spring, a website came along called JailbreakMe.com that made it trivial to jailbreak your own iPhone or iPad. Last week, a technique for remote jailbreaking appeared on the site. It's now possible to access the operating system of an iPhone or iPad owned by someone else.
An attacker would get "fairly complete control of affected devices," says Michael Price, an operations manager for McAfee Labs. No such attacks are known to have happened yet, he says.
For the moment, the most visible concern for Apple has been pranksters going into Apple and Best Buy retail stores and jailbreaking display models, according to tech blog Engadget. Yet, the security and privacy issues are serious.
Security experts expect the pattern that has come to dominate the PC world to begin to permeate smartphones. Bad guys continually flush out new security flaws in PCs, then tap into them to launch malicious attacks. Good guys, meanwhile, scramble to patch and block.
Now, cybercriminals are rapidly adapting PC hacking techniques to all smartphone platforms, including Symbian, Google Android, Windows Mobile, RIM BlackBerry and Apple iOS.
"It's a brand new game with new rules," says Dror Shalev, chief technology officer of DroidSecurity, which supplies protection for Google Android phones. "We're seeing rapid growth in threats as a side effect of the mobile Web app revolution."
IPhones, in particular, have become a pop culture icon in the U.S., and now the iPad has grabbed the spotlight. "The more popular these devices become, the more likely they are to get the attention of attackers," says Joshua Talbot, intelligence manager at Symantec Security Response.
Apple's problem is singular. The company has made a big deal about hiding technical details of iOS, allowing only approved Web apps to tie in. This tight control initially made it easier to keep iOS secure. But now Apple may have to share iOS coding with anti-virus firms, says Sorin Mustaca, development manager for anti-virus firm Avira.
Windows, Google, Nokia and RIM share such coding to help anti-virus firms develop protections. "Apple does not allow this, making it challenging for anti-virus vendors to create third-party protection for iPhones and iPads," Mustaca says.
Pressure is building. Mikko Hyponnen, senior researcher at anti-virus firm F-Secure, says hackers are likely working on a worm to take control of jailbroken iPads and iPhones. "My guess is we'll see it within a week," Hyponnen says. "There's very little users can do to protect themselves beforehand."
Apple is aware of the threat, but not saying much publicly. "We'll do everything we can to make sure this is not an issue for our customers," Kerris says.
Apple must coordinate patching with some 15 phone companies worldwide, says John Hering, CEO of mobile security firm Lookout. And iPad and iPhone users likely will have to manually install the patch via iTunes. "We're in a cat-and-mouse game with openness and security at odds, and consumers stuck right in the middle," Hering says.
(c) 2010, USA Today.
Visit USA Today on the Internet at http://www.usatoday.com/
Distributed by McClatchy-Tribune Information Services.
-
Germany warns of Apple security problem
Aug 04, 2010 |
not rated yet |
0
-
Apple to fix security hole in iPhone software
Aug 05, 2010 |
not rated yet |
0
-
New gov't rules allow unapproved iPhone apps (Update 3)
Jul 26, 2010 |
not rated yet |
0
-
Google's AdMob attacks Apple's new mobile ad rules
Jun 09, 2010 |
not rated yet |
0
-
How Secure are iPhone and Android Apps
Apr 01, 2010 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Calling function with no input argument
14 hours ago
-
Force free body diagram problem on gym equipment
14 hours ago
-
Empirical data regarding shower heads and water
22 hours ago
-
feed hold button on CNC lathe
Feb 09, 2012
-
RFAC in Fortran
Feb 09, 2012
-
dynamics 2/32
Feb 08, 2012
- More from Physics Forums - General Engineering
More news stories
Google users warned of threat to smartphone wallets
Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.
6 hours ago |
5 / 5 (2) |
0
Anonymous knocks CIA website offline (Update)
The website of the Central Intelligence Agency was inaccessible on Friday after the hacker group Anonymous claimed to have knocked it offline.
8 hours ago |
5 / 5 (8) |
13
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
16 hours ago |
4.9 / 5 (8) |
6
|
New power source discovered
(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.
Technology / Energy & Green Tech
15 hours ago |
4.8 / 5 (25) |
8
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
16 hours ago |
4.3 / 5 (12) |
22
|
Humans may have helped the decline of African rainforests 3000 years ago
(PhysOrg.com) -- Large areas of rainforests in Central Africa mysteriously disappeared over three thousand years ago, to be replaced by savannas. The prevailing theory has been that the cause was a change ...
Complex wiring of the nervous system may rely on a just a handful of genes and proteins
Researchers at the Salk Institute have discovered a startling feature of early brain development that helps to explain how complex neuron wiring patterns are programmed using just a handful of critical genes. ...
The power of estrogen -- male snakes attract other males
A new study has shown that boosting the estrogen levels of male garter snakes causes them to secrete the same pheromones that females use to attract suitors, and turned the males into just about the sexiest ...
Putting the squeeze on planets outside our solar system
(PhysOrg.com) -- Using high-powered lasers, scientists at Lawrence Livermore National Laboratory and collaborators discovered that molten magnesium silicate undergoes a phase change in the liquid state, abruptly ...
Could Venus be shifting gear?
(PhysOrg.com) -- ESAs Venus Express spacecraft has discovered that our cloud-covered neighbour spins a little slower than previously measured. Peering through the dense atmosphere in the infrared, the ...
Fool's gold may prove an unlikely alternative to overexploited catalytic materials
Catalytic materials, which lower the energy barriers for chemical reactions, are used in everything from the commercial production of chemicals to catalytic converters in car engines. However, with current catalytic materials ...
Aug 09, 2010
Rank: 5 / 5 (2)
No. It's to download /native/ apps, not /web/ apps. You don't download web apps, you just visit them via a web browser, and web apps do NOT need to be approved by Apple (and aren't). ONLY native apps need Approval from Apple (unless you've rooted or jailbroken your phone).
Not if the iPhone was jailbroken with JailBreakMe.com, as part of that hack is to close the very security vulnerability that allowed it in the first place. Of course, running a jailbroken phone means you put more of your phone's security in your own hands and have to be smarter about what you choose to install. In that regard, jailbroken phones /could/ have a higher likelihood of becoming infected (depending on the security practices of each, individual phone's user).
Aug 09, 2010
Rank: 5 / 5 (1)
There's a lot to be said for open source, in addition to being able to take control over your own phone (rooting, jailbreaking, etc.) CSharpner's spot on about this.